RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
{ "severity": "HIGH", "nvd_published_at": "2015-02-16T15:59:00Z", "github_reviewed_at": "2024-04-29T16:06:47Z", "cwe_ids": [ "CWE-200" ], "github_reviewed": true }